How do we define Customer Data and roles under GDPR
We define Customer Data as all data that the customer (the "Customer") provides to us or that we process on behalf of the Customer as part of providing the services. For all personal data that we process as part of providing the services, the Customer is the Data Controller as defined by Article 4(7) of the General Data Protection Regulation (GDPR). We act as the Data Processor when we process personal data on behalf of the Customer. As Data Controller, the Customer is responsible for ensuring there is a lawful basis for processing all personal data contained in the Customer Data, and for configuring the service in a way that complies with the Customer’s own privacy policy, the GDPR, and other applicable data privacy regulations. As Data Processor, we will only process data, information, and material in order to provide the service to the Customer, including support, service, and maintenance activities, and we will not process data for any other purposes unless there is a legal obligation to do so.